Threats Tagged 'persistence mechanisms'
View all threats tagged with 'persistence mechanisms'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'persistence mechanisms'
Click on any threat for detailed analysis and mitigation recommendations
Threat actors exploited ChatGPT's Custom GPT feature to impersonate legitimate ChatGPT models, directing victims through sponsored Google ads to malicious Custom GPTs titled 'Plus 5.6'. These instances served fake service availability notices, redirecting users to Google Sites pages hosting ClickFix lures disguised as CloudFlare CAPTCHA checks. Victims were tricked into executing PowerShell commands that downloaded malicious MSI installers. The attack chain employed DLL sideloading through legitimate Canon-signed and later Stardock-signed executables, establishing dual persistence mechanisms via registry Run keys and scheduled tasks. The multi-stage infection involved obfuscated scripts, encrypted payloads hidden in WAV files and NuGet packages, and ultimately deployed a feature-rich remote access trojan with capabilities including remote desktop, browser hijacking, credential theft, and follow-on payload delivery. Huntress investigated approximately 40 incidents linked to this campaign, with confirmed Cus... Join the discussion | AlienVault OTX General | 10/03/2026, 16:26:01 UTC Added: 09/29/2026, 19:21:24 UTC |
RedHook is an Android Remote Access Trojan that has re-emerged with significant enhancements, particularly in privilege abuse capabilities. The malware autonomously exploits Android's ADB Wireless Debugging features to obtain shell-level access, integrating the Shizuku framework to execute protected system APIs. Recent activity shows expansion beyond Vietnam to Indonesia, targeting Southeast Asian users through spoofed government and financial websites. Malicious APKs are hosted on trusted platforms like AWS S3 and GitHub repositories. The current version supports 53 distinct server-issued commands and employs sophisticated persistence mechanisms including foreground activity spoofing, silent media playback, and cross-process monitoring. Distribution relies on social engineering via phone calls and messaging applications, tricking victims into downloading malicious APKs and enabling Accessibility services under false pretenses. Join the discussion | AlienVault OTX General | 07/09/2026, 13:20:35 UTC Added: 07/10/2026, 07:32:34 UTC |
NightSpire ransomware, first discovered in February 2025, presents a categorization challenge regarding whether it operates as Ransomware-as-a-Service (RaaS). Analysis of two incidents from December 2025 and March 2026 reveals significant variations in tactics, techniques, and procedures between attacks. The March 2026 incident involved threat actors installing Chrome Remoting Desktop and AnyDesk for persistence, using Everything and 7Zip for data staging, MEGASync for exfiltration, and deploying VMWare Workstation and WPS Office. The attacker accessed systems via RDP days before detection. Comparison with the December 2025 incident shows evolution in the ransomware encryptor, including modified ransom note filenames and contents. These variations in TTPs and indicators suggest either operational evolution or involvement of multiple affiliates, demonstrating that ransomware indicators aren't consistent across campaigns. Join the discussion | AlienVault OTX General | 04/08/2026, 09:15:51 UTC Added: 04/08/2026, 11:05:57 UTC |
An unidentified spyware called Batavia has been targeting Russian industrial organizations since July 2024 through a sophisticated phishing operation. The campaign uses bait emails disguised as contract agreements to trick employees into downloading malicious scripts, initiating a multi-stage infection process. The spyware's ultimate goal is to exfiltrate sensitive internal documents and system data. The attack involves multiple stages, including downloading encrypted VBS scripts, executing Delphi-written executables, and deploying C++-based malware for expanded data theft. Batavia employs advanced evasion tactics and persistence mechanisms, making it a significant threat to organizational security. The campaign remains active, with potential for further damage due to its ability to download additional payloads. Join the discussion | AlienVault OTX General | 07/09/2025, 03:05:16 UTC Added: 07/09/2025, 11:54:31 UTC |
Showing 1 to 4 of 4 results